-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 19 Feb 2025 14:42:13 +0100 Source: xorg-server Binary: xnest xnest-dbgsym xserver-xephyr xserver-xephyr-dbgsym xserver-xorg-core xserver-xorg-core-dbgsym xserver-xorg-core-udeb xserver-xorg-dev xserver-xorg-legacy xserver-xorg-legacy-dbgsym xvfb xvfb-dbgsym Architecture: mips64el Version: 2:21.1.7-3+deb12u9 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Salvatore Bonaccorso Description: xnest - Nested X server xserver-xephyr - nested X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xserver-xorg-legacy - setuid root Xorg server wrapper xvfb - Virtual Framebuffer 'fake' X server Changes: xorg-server (2:21.1.7-3+deb12u9) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Cursor: Refuse to free the root cursor (CVE-2025-26594) * dix: keep a ref to the rootCursor (CVE-2025-26594) * xkb: Fix buffer overflow in XkbVModMaskText() (CVE-2025-26595) * xkb: Fix computation of XkbSizeKeySyms (CVE-2025-26596) * xkb: Fix buffer overflow in XkbChangeTypesOfKey() (CVE-2025-26597) * Xi: Fix barrier device search (CVE-2025-26598) * composite: Handle failure to redirect in compRedirectWindow() (CVE-2025-26599) * composite: initialize border clip even when pixmap alloc fails (CVE-2025-26599) * dix: Dequeue pending events on frozen device on removal (CVE-2025-26600) * sync: Do not let sync objects uninitialized (CVE-2025-26601) * sync: Check values before applying changes (CVE-2025-26601) * sync: Do not fail SyncAddTriggerToSyncObject() (CVE-2025-26601) * sync: Apply changes last in SyncChangeAlarmAttributes() (CVE-2025-26601) Checksums-Sha1: 89c68c5bc44acd2e04edba333c62c9a2a6e16845 2742728 xnest-dbgsym_21.1.7-3+deb12u9_mips64el.deb 7ac35861844eea9285880275e16d3da2eebaae82 2936400 xnest_21.1.7-3+deb12u9_mips64el.deb 11c6f75bb73b2e3e1dd40e200e493fe5c22c4565 14619 xorg-server_21.1.7-3+deb12u9_mips64el-buildd.buildinfo d52beb5668686d35f0be58237f64b6c45256cd25 4030580 xserver-xephyr-dbgsym_21.1.7-3+deb12u9_mips64el.deb 9fc3d8ea386e90b81ae33f84e99f121e7d5a0a88 3176952 xserver-xephyr_21.1.7-3+deb12u9_mips64el.deb ccfa0f1137a88e85e3eb9767f51f57c406586bfd 5883232 xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_mips64el.deb 342138a995695c2c934758349d7c7fcf5214f692 842100 xserver-xorg-core-udeb_21.1.7-3+deb12u9_mips64el.udeb 28aeaf39b28c12dd8e7292d89949edc93993995f 3546268 xserver-xorg-core_21.1.7-3+deb12u9_mips64el.deb 6399840e652a696995e2ec58ee67291f1c67c71c 2554512 xserver-xorg-dev_21.1.7-3+deb12u9_mips64el.deb 35bb5d1eeb654bb39e6de6063eb6031f9fe679e0 9712 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_mips64el.deb fa519ef4c803aec93cb6751568acf2b703651a5b 2388672 xserver-xorg-legacy_21.1.7-3+deb12u9_mips64el.deb 07a79a7348824a330463d1f99415cc2f90a7abb3 3338316 xvfb-dbgsym_21.1.7-3+deb12u9_mips64el.deb eba5a6a5089eb95e832447b90fd464a15239eae9 3058012 xvfb_21.1.7-3+deb12u9_mips64el.deb Checksums-Sha256: d9d855556152550cb19f3521626bf4ea8aad81f21da59aa9db35efd780a9aa00 2742728 xnest-dbgsym_21.1.7-3+deb12u9_mips64el.deb e15c6a598a0fc1001ea39c55938a12870c53483d059fb065cdf8c075875287a2 2936400 xnest_21.1.7-3+deb12u9_mips64el.deb 291d37fe7c4efbeb0b14f576b58568192c5505418b74664d538b1034ff4e1048 14619 xorg-server_21.1.7-3+deb12u9_mips64el-buildd.buildinfo 180686c32375918036178b919a524e618c62d6ef3ef63cc9f21746e881481a64 4030580 xserver-xephyr-dbgsym_21.1.7-3+deb12u9_mips64el.deb f63faf7d3c733fe83decf49cbf5cb9708abf027d18e236e859bb36c1320975d9 3176952 xserver-xephyr_21.1.7-3+deb12u9_mips64el.deb 7d1731c574e8bb268f929fd15b2c0731f3f8b2869e5056982bbe9f1a2b11f7be 5883232 xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_mips64el.deb 87d72fec04d5d3c7badb919193b71cfc829d85277fbd859f5830024b0a32bce8 842100 xserver-xorg-core-udeb_21.1.7-3+deb12u9_mips64el.udeb bef3297113ae9783adb44d78ae465cefebb93e5df5c9bd60b409934eb076d6e3 3546268 xserver-xorg-core_21.1.7-3+deb12u9_mips64el.deb 4af95d071012ae0fb883ed03fc9b896c2a7a4675e38629bc3da6a0c1f7e32d0d 2554512 xserver-xorg-dev_21.1.7-3+deb12u9_mips64el.deb d36f1ffb14d1539eef6c3acd81d7ad699656a50e2cea22f6a248bb06b2decf08 9712 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_mips64el.deb bca6fdd7b11b2759756488751a2393d275c306a375c605c7576d77b344834d64 2388672 xserver-xorg-legacy_21.1.7-3+deb12u9_mips64el.deb bf16e71ebf289126d8bf897653a47d8fc196cf67d4482305148d2ac2bb36aeb2 3338316 xvfb-dbgsym_21.1.7-3+deb12u9_mips64el.deb 6f4b47eae5e48cf4b3f339bbe39a498365803b3809c7ee91799813dc2dbefb2d 3058012 xvfb_21.1.7-3+deb12u9_mips64el.deb Files: ccbb72b5ad838a2ce9200e73e2696966 2742728 debug optional xnest-dbgsym_21.1.7-3+deb12u9_mips64el.deb 090b38767a963c095a23bb48abd281ee 2936400 x11 optional xnest_21.1.7-3+deb12u9_mips64el.deb 91d0a8410b979edd59c675467dd14d91 14619 x11 optional xorg-server_21.1.7-3+deb12u9_mips64el-buildd.buildinfo 01f7bc458f54846c745d9aa85c9b0b74 4030580 debug optional xserver-xephyr-dbgsym_21.1.7-3+deb12u9_mips64el.deb 20e18e0097c53793eb7c74003e41800d 3176952 x11 optional xserver-xephyr_21.1.7-3+deb12u9_mips64el.deb 6d8f16cc0a3b86188a2e1851f80eb91d 5883232 debug optional xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_mips64el.deb 44cea08935477e6b296f1f4ba50e0b84 842100 debian-installer optional xserver-xorg-core-udeb_21.1.7-3+deb12u9_mips64el.udeb d09ff18a04f025c992c76d8e6e92fca4 3546268 x11 optional xserver-xorg-core_21.1.7-3+deb12u9_mips64el.deb 9e7e365167c686c49d4308bb44a2d9fd 2554512 x11 optional xserver-xorg-dev_21.1.7-3+deb12u9_mips64el.deb 6427d417e84ac1e7448f5d8f0b5366b7 9712 debug optional xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_mips64el.deb 0e2a07c5540288ea02815198a2b524a7 2388672 x11 optional xserver-xorg-legacy_21.1.7-3+deb12u9_mips64el.deb 4d4a68b0632966b75c2ae35f5db233ca 3338316 debug optional xvfb-dbgsym_21.1.7-3+deb12u9_mips64el.deb 1b645457a7b7e187f3bdbca1ce72d385 3058012 x11 optional xvfb_21.1.7-3+deb12u9_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERbXMbY9VMQqnSaVEV4aVsMglzVcFAme2MfAACgkQV4aVsMgl zVdfYg/+Mu1N5Rirds2cLvz2L2QNoMQFTZf6n1rQ0m1uJeIqrHI0lLs5W6lcPn6O CUtC9QRinyPd8HH2oM80wrm5aSrj+fYSgJAHv2GYTl06m0JpPB1EBkfmtd2Wrz2c DYNLfb5zsKtpTBXfcyP0IBkG5RS31vyL2LXS0Hfud2TdHiNGk/NpZZ2JAybUaqfR eIKmiBOzW7nhVJJxKMhueKywABjsGr4VBUIaLSnm0fEHIT4x2FnlocHglu6PbHO8 XPZfKaBAFWIAwIIOzJwuGS88Bp+WYgxwGn/jvTdsNU0Ao+lhBeiUYKTu50gfJPja LSs4gGVu9c3ECtiobYHM4QG64NSr1518AL/YTFTwocxkLozYOyKuVi7seYKJ+1Od 3CsDJTPCPJdTV9d+ScpMOLyHquXZTBWog3f7qrnceh216XuDFJn0v7Jp0LDUePwm Y3Bnqp7ttmD5rXFYnQLGjJTtOHfKVoKf8yYXbRrKKohAGEOL0aup4+KUk2SlAX8R f2kgkckepg53rOC2v/Dohss4Vld9bXVbJadunXmx31YY0Gu2Wue+JqohSonGbWVU 7wnO+1ooifam7Hmuq3KcHFkVLwU0tYsElgLWGny0wuc8v3Ksc3cLVAtlw5JB7Uh2 C+99lJr9vq19COfxKID+wI1uYCuGNXK66hL2NFq7MIVT5ejZu/M= =qgd2 -----END PGP SIGNATURE-----